UK GDPR: what it asks of a training dataset list
When the company is established in the UK, or processes personal data of people in the UK: the same lines under the UK regime, with Article 8A deciding whether reuse for a new purpose is compatible. The UK GDPR trigger is separate from the GDPR one.
Cited when the UK GDPR trigger is ticked: established in the UK, or processing personal data of people in the UK.
Three kinds of data, three conditions
- Article 9 special category data (health, genetic, biometric for identification, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sex life or sexual orientation): Processing needs one of the Article 9(2) conditions in addition to a lawful basis under Article 6.
- criminal offence data (GDPR Art. 10) (criminal convictions and offences, and related security measures): Processing is allowed only under the control of official authority or where law authorises it with appropriate safeguards, in addition to a lawful basis; it is not Article 9 data.
- children's personal data (heightened protection, not Art. 9) (personal data about children): Children merit specific protection; where consent is the basis for an online service offered directly to a child, Article 8 sets the age and the parental authorisation. It is not Article 9 data.
Findings that cite it
| Finding | Clause |
|---|---|
| Origin not recorded | UK GDPR Art. 30 |
| Personal data with no lawful basis recorded, or reused from another purpose | UK GDPR Art. 6 UK GDPR Art. 8A UK GDPR Art. 5 |
| Article 9, criminal offence or children's data declared | UK GDPR Art. 35 UK GDPR Art. 9 UK GDPR Art. 10 UK GDPR Art. 8 |
| Older than your N-year policy threshold (a threshold you set, not a legal deadline) | UK GDPR Art. 5 |
| Content where a label belongs | UK GDPR Art. 5 |
| Vendor data with no provider named | UK GDPR Art. 28 |
Source classes anchored here
35UK GDPR: every clause cited
11 of the 44 heldThe requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.
UK GDPR Art. 5Principles relating to processing of personal dataPersonal data must be processed lawfully, fairly and transparently; collected, whether from the data subject or otherwise, for specified, explicit and legitimate purposes and not further processed by or for the controller in a way incompatible with the purposes for which the controller collected it (Article 8A decides compatibility); adequate, relevant and limited to what is necessary; accurate and kept up to date, with inaccurate data erased or rectified without delay; kept in identifiable form no longer than necessary, with longer storage only for archiving, research or statistics carried out under Article 84B; and secured against unauthorised or unlawful processing and accidental loss, destruction or damage. The controller is responsible for, and must be able to demonstrate, compliance (accountability). Article 5(3) adds that processing is not lawful merely because it is compatible with the original purpose: a lawful basis under Article 6 is still needed.
UK GDPR Art. 6Lawfulness of processingProcessing is lawful only if at least one basis applies: consent for specific purposes, contract with the data subject, legal obligation, vital interests, a public task laid down in domestic law or relevant international law (section 9A of the 2018 Act), a recognised legitimate interest, or legitimate interests not overridden by the data subject's interests, rights and freedoms (particularly where the data subject is a child). Neither legitimate-interest basis is open to public authorities performing their tasks. A recognised legitimate interest (Article 6(1)(ea)) applies only where a condition in Annex 1 is met: disclosure on request to a body that states it needs the data for a public task, national security, public security or defence, responding to an emergency, detecting or preventing crime or prosecuting offenders, and safeguarding a vulnerable individual (under 18, or 18 or over and at risk); no balancing test is required for these. Article 6(11) gives direct marketing, intra-group transmission for internal administration and network and information security as examples of processing that may be necessary for legitimate interests, which still need the balancing test.
UK GDPR Art. 7Conditions for consentWhere processing rests on consent the controller must be able to show the data subject consented. A consent request inside a written declaration covering other matters must be clearly distinguishable, intelligible, easily accessible and in plain language, and any part that infringes the Regulation does not bind. The data subject may withdraw consent at any time, must be told so before consenting, and withdrawing must be as easy as giving consent; withdrawal does not undo earlier lawful processing. Whether consent is freely given takes utmost account of whether a contract or service is made conditional on consent to processing the contract does not need. Consent to an area of scientific research counts as consent where the conditions in Article 4(6) are met.
UK GDPR Art. 8Conditions applicable to a child's consent in relation to information society servicesWhere consent is the basis for offering an information society service directly to a child, processing is lawful for a child aged 13 or over; below 13 it is lawful only with consent given or authorised by the holder of parental responsibility, and the controller must make reasonable efforts, with available technology, to verify that authorisation. Preventive or counselling services are excluded. Since 29 April 2026 (Children's Wellbeing and Schools Act 2026) the Secretary of State may by regulations raise the age to any age up to 16, for all or specified services, and Article 8ZA lets regulations impose age verification requirements; no such regulations are recorded in the held text.
UK GDPR Art. 8APurpose limitation: further processingWhether processing for a new purpose is compatible with the purpose of collection is decided by weighing, among other things, the link between the purposes, the context of collection and the relationship with the data subject, the nature of the data (special category or criminal offence data), the possible consequences, and safeguards such as encryption or pseudonymisation. Further processing is treated as compatible where the data subject consents to a specified, explicit and legitimate new purpose; where it is research, archiving or statistics under Article 84B; where it ensures or demonstrates compliance with Article 5(1); where an Annex 2 condition is met (disclosure on request for a public task, archiving disclosures of consent-based data, public security, emergencies, crime, vital interests, safeguarding vulnerable individuals, tax, legal obligations); or where it is necessary for an Article 23(1)(c) to (j) objective and authorised by law. Data collected on consent may be reused only with fresh consent or for compliance, or under Annex 2 or an authorised objective where consent cannot reasonably be sought.
UK GDPR Art. 9Processing of special categories of personal dataProcessing data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic data, biometric data used to identify a person uniquely, health data, or data about sex life or sexual orientation is prohibited unless a lawful basis under Article 6 applies together with a condition in Article 9(2): explicit consent, employment, social security and social protection law, vital interests where consent is impossible, not-for-profit bodies' members, data manifestly made public, legal claims and courts, substantial public interest, health and social care, public health, or archiving, research and statistics under Article 84B. Where the condition needs a basis in domestic law, section 10 and Schedule 1 of the 2018 Act supply it (often with an appropriate policy document); health and social care processing must be by or under the responsibility of a professional bound by secrecy. Article 11A lets regulations add descriptions of processing to the prohibition and set which exceptions apply to them.
UK GDPR Art. 10Processing of personal data relating to criminal convictions and offencesPersonal data about criminal convictions, offences or related security measures, processed on an Article 6 basis, may be processed only under the control of official authority or where authorised by domestic law or relevant international law with appropriate safeguards; section 10(5) and Schedule 1 of the 2018 Act supply the domestic-law conditions and section 11(2) defines the data to include allegations, proceedings and sentencing. A comprehensive register of criminal convictions may be kept only under official authority.
UK GDPR Art. 14Information to be provided where personal data have not been obtained from the data subjectWhere data come from elsewhere the controller must give the Article 13 information plus the categories of data and the source (including whether publicly accessible), within a reasonable period and at the latest one month after obtaining the data, or at first communication with the data subject, or when first disclosing to another recipient, and must tell the data subject before further processing for a new purpose. The duty falls away where the data subject already has the information, where obtaining or disclosure is expressly required by domestic law with appropriate protections, where professional secrecy requires confidentiality, where providing the information is impossible or would involve disproportionate effort (judged by the number of data subjects, the age of the data and the safeguards), or where it would render impossible or seriously impair the purposes; a controller relying on the last two must protect the data subject's interests, including by publishing the information.
UK GDPR Art. 28ProcessorA controller may use only processors giving sufficient guarantees of appropriate measures. A processor may not engage a sub-processor without prior specific or general written authorisation, and under general authorisation must notify changes so the controller can object. Processing must be governed by a written contract or legal act setting out the subject matter, duration, nature, purpose, data types, data subjects and the controller's rights and obligations, and requiring the processor to act only on documented instructions (including on transfers), bind its staff to confidentiality, take Article 32 measures, respect sub-processing conditions, assist with rights requests and with Articles 32 to 36, delete or return data at the end, and provide information and allow audits, informing the controller if an instruction infringes the law. Sub-processors carry the same obligations and the processor stays liable for them. The Commissioner may adopt standard contractual clauses; a processor that determines purposes and means is treated as a controller.
UK GDPR Art. 30Records of processing activitiesEach controller (and representative) must keep a written, including electronic, record of its processing with its name and contacts, purposes, categories of data subjects and data, recipients, transfers abroad with Article 49(1) second-subparagraph safeguards documented, erasure time limits where possible, and a general description of security measures. Each processor must keep a record of the categories of processing it carries out for each controller, transfers and security measures. Records must be made available to the Commissioner on request. Organisations with fewer than 250 employees are exempt unless the processing is likely to result in a risk, is not occasional, or includes special category or criminal offence data.
UK GDPR Art. 35Data protection impact assessmentBefore processing likely to result in a high risk, particularly with new technologies, the controller must assess the impact, seeking the DPO's advice. A DPIA is required in particular for systematic and extensive automated evaluation with legal or similarly significant effects, large-scale special category or criminal offence data, and large-scale systematic monitoring of public areas, and for the kinds of processing on the Commissioner's published list. The DPIA must contain a description of the processing and purposes, an assessment of necessity and proportionality, an assessment of risks to individuals, and the measures to address them; approved codes are taken into account, data subjects' views sought where appropriate, and the assessment reviewed when the risk changes.